# Marriott International

**Canonical:** https://apis.io/providers/marriott/  
**Website:** https://www.marriott.com/  
**APIs profiled:** 6

Marriott International is the world's largest hotel group by room count, headquartered in Bethesda, Maryland, United States, operating and franchising roughly thirty brands from The Ritz-Carlton, St. Regis and W through Marriott Hotels, Sheraton, Westin and Courtyard down to Fairfield, Moxy and StudioRes, plus the Homes & Villas by Marriott Bonvoy home-rental marketplace and the Marriott Bonvoy loyalty program. It sits on the supply side of the travel distribution chain: it publishes rates and availability into every major global distribution system — Marriott's own travel-agent site states it "participates in the following GDS: Amadeus, Sabre, Travelport (Apollo/Galileo, and Worldspan)" — sells through the OTAs, connects short-term-rental supply through a channel-connectivity partner program, and spends heavily to pull demand back to direct booking on Marriott.com and the Bonvoy app. Its API posture is closed. A Broadcom Layer7 developer portal exists at devportalprod.marriott.com and returns HTTP 200, but its anonymous API catalog is literally empty and the portal's own home content returns HTTP 401 — there is no self-serve signup, no public API reference, no published rates/availability/booking API, no sandbox, no SDK, no changelog and no exit path. The only Marriott OpenAPI documents that can be read without a contract are eight internal and partner-facing specifications left publicly readable on SwaggerHub under the "marriott-api" owner; six are mirrored here verbatim as evidence. Everything a developer would actually want is behind a partner relationship, a travel-agent registration, or a GDS or channel-manager contract.

## Kin Score — 33.2 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 33.2).

| Facet | Score |
|---|---|
| Discoverability | 83.3 |
| Contract Quality | 46.6 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 10.5 |
| Developer Ergonomics | 28.0 |
| Commercial Clarity | 21.1 |
| Access Clarity | 21.1 |

## Agent readiness — 39.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (6)

- **Marriott TIP Internet Portal API** — Partner-facing API used by Marriott's in-hotel internet (TIP) provider integration to generate a guest landing-page URL, validate a guest's room number and last name against the...
- **Marriott Loyalty Account Merge API** — Internal Marriott Bonvoy loyalty operation that merges or transfers one member profile into another, keyed on a member account type code and member account unique identifier. Do...
- **Marriott Data Collection API** — Internal Marriott stay-event API that captures and publishes additional event data for a reservation confirmation number, described by its own OpenAPI as feeding a downstream co...
- **Marriott Commerce Payment Processor API** — Internal Marriott commerce API that submits a payment to a payment processor over an XML FreedomPay Freeway service operation. Its OpenAPI info block names the "Marriott API Tea...
- **Marriott Finance Status Notifier API** — Internal Marriott finance application API that receives processing status for files generated by Marriott's finance adapters, with status, data, config-watcher and Spring Boot a...
- **Marriott Hotel Operations ARA Preview Submit API** — Internal Marriott hotel-operations API that submits a preview request for ARA automated room assignment. The OpenAPI document declares no servers at all, which is itself the fin...

## Agentic access (1)

- **Marriott Agentic Access** — 13 operations · 11 acting · 1 human-in-the-loop

## Security (3)

- **Marriott Authentication** — http/oauth2 · 4 schemes
- **Marriott Domain Security** — TLSv1.3 · DMARC
- **Marriott Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Tags

Travel, United States, Hospitality, Hotels, Booking, Distribution, Loyalty, Short-Term Rental, Corporate Travel

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/marriott/). Scores are computed from the provider's own public artifacts under a published rubric.
